cms.teleglobals.com

From On-Premises to AWS: A Secure Cloud Migration for a Growing SaaS Platform

Executive Summary

A SaaS company running a multi-module application platform on ageing on-premises infrastructure partnered with Teleglobal to move to AWS. The platform had outgrown its existing setup. Infrastructure could not scale with demand, deployments were manual, and there were no formal security controls in place. Teleglobal designed a production-grade AWS architecture and ran the migration across Production and UAT environments in a structured, phased approach, with full encryption in place from day one and no disruption to the live platform during cutover. 

On-Premises to AWS Cloud Migration

Customer Overview

The client is a SaaS company in India building a multi-module application platform for a growing user base. As the platform grew, the on-premises infrastructure it ran on started showing its limits. Manual deployments slowed the team down. Security controls were informal. There was no visibility into performance or cost. The business needed a cloud environment built to grow with it. 

The Problem

The on-premises setup had served its purpose, but it was not built for scale. Four things were holding the business back. 

  1. Scalability – The infrastructure had no flexibility. Handling traffic spikes meant manual work, and the team had already seen performance issues during busy periods. 
  1. Security gaps – There was no encryption for data at rest or in transit, no central identity management, and no audit logs. Compliance was becoming a concern as the client base grew. 
  1. Manual deployments – Every release was slow, risky, and dependent on specific team members. There was no structured process. 
  1. No visibility – Without monitoring or cost tracking, the team had no visibility into what was running, how it was performing, or what it was costing. 

The client needed to migrate without disrupting existing operations. This required a structured, thoroughly tested, and reversible approach at every stage.

Before vs After On-premises to AWS Cloud Migration

The Solution

Teleglobal designed and ran a phased migration to AWS, covering architecture design, environment setup, database migration, application deployment, security hardening, and go-live. Each phase was checked before the next one started. 

Assessment and Architecture Design

The engagement started with mapping the existing environment: application modules, server details, storage needs, IP dependencies, and access requirements. A target AWS architecture was then designed covering VPC networking, compute, database, storage, security, and monitoring for both Production and UAT. The cutover plan, backup approach, and rollback steps were agreed with the client before any migration work began. 

AWS Environment Setup

A custom VPC was set up with public and private subnets, Internet Gateway, NAT Gateway, and route tables. Security Groups and Network ACLs were configured using least-privilege rules. AWS IAM was set up with users, groups, roles, and policies mapped to each team’s access needs. OpenVPN was configured on a dedicated server so the engineering team could access private resources without exposing anything to the public internet. 

Compute, Database, and Storage 

Application modules were moved to EC2 instances in private subnets, each set up with security groups and IAM roles. An Application Load Balancer was placed in the public subnet to distribute traffic. AWS WAF was connected to the ALB to protect against web attacks. Amazon RDS for PostgreSQL was deployed in a private subnet with encryption, automated backups, and CloudWatch monitoring. Three S3 buckets were set up for application data, backups, and logs, all encrypted using AWS KMS.

Security and Key Management

AWS KMS was set up for centralised encryption key management across S3 and other resources. AWS Secrets Manager replaced informal credential storage, keeping application secrets, API keys, and configuration values secure. MFA was enforced for all IAM users, and role-based access was applied across EC2 and S3 to restrict access to only the people and systems that needed it. 

Monitoring, Validation, and Go-Live

Amazon CloudWatch was set up with logs, metrics, alarms, and dashboards across all deployed services. Tests were run in UAT before any production changes were made. The team validated each phase before moving to the next. DNS cutover and the final production switch were done with the client, and full infrastructure documentation was handed over covering networking, IAM policies, endpoints, and security settings. 

AWS Services Used

AWS Service Role in This Engagement 
Amazon VPC Isolated network with public and private subnets 
Amazon EC2 Compute for all application modules 
Application Load Balancer Traffic distribution across EC2 instances 
AWS WAF Web application protection at the ALB layer 
NAT Gateway Controlled internet access for private subnet resources 
OpenVPN Secure admin and developer access without public exposure 
Amazon RDS for PostgreSQL Managed database with encryption and automated backups 
Amazon S3 (3 Buckets) Application data, backups, and logs 
AWS KMS Centralised encryption key management 
AWS Secrets Manager Secure storage of credentials and application secrets 
AWS IAM Identity and access with least-privilege policies 
Amazon CloudWatch Monitoring, logging, alarms, and dashboards 

Business Impact

  • Both Production and UAT environments were migrated and validated successfully, with all data encrypted at rest and in transit. 
  • CloudWatch dashboards and alerts were set up across all services, giving the team full infrastructure visibility with cost tagging and performance monitoring in place. 
  • All credentials were moved from informal storage to AWS Secrets Manager, with IAM roles and least-privilege policies applied across all services. 
  • The platform can now scale compute on demand, removing the main bottleneck on growth. 
  • Security improved across the board: encryption enforced, IAM tightened, audit logs active, and WAF protecting the application layer. 
  • Manual deployment risk removed through structured environment separation, documented runbooks, and CloudWatch alerting. 
Business Impact of AWS Cloud Migration

Bottom Line

The client moved from a manually managed, on-premises environment with no formal security controls to a production-grade AWS setup through a structured, phased migration. Every step was validated with the team before go-live, and the platform stayed up throughout the process. 

The new environment is secure, monitored, and ready to grow with the business. As an AWS Advanced Consulting Partner, Teleglobal handles every migration from the first scoping call through to final documentation and handover.